Vulnerability record · CVE-2020-15922 · published 24 July 2020
CVE-2020-15922: Mida eFramework OS command injection enables root RCE
Midasolutions · Eframework
Mida eFramework 2.9.0 contains an OS command injection flaw (CWE-78) that lets an attacker run arbitrary commands and achieve remote code execution with administrative (root) privileges. The description states authentication is required, yet the CVSS 3.1 vector is PR:N, so the record is internally inconsistent on whether credentials are needed. Because successful exploitation yields root-level code execution, the flaw is severe for any exposed deployment.
Description
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote code execution as root with a critical CVSS score, public exploit references and very high EPSS make this an urgent fix despite the authentication ambiguity.
What it is
Mida eFramework 2.9.0 contains an OS command injection flaw (CWE-78) that lets an attacker run arbitrary commands and achieve remote code execution with administrative (root) privileges. The description states authentication is required, yet the CVSS 3.1 vector is PR:N, so the record is internally inconsistent on whether credentials are needed. Because successful exploitation yields root-level code execution, the flaw is severe for any exposed deployment.
Impact
An attacker who can reach the vulnerable functionality gains arbitrary command execution as root, effectively full control of the host. That permits data theft, service disruption, persistence and lateral movement from the compromised server.
Attack surface
The flaw is network-reachable (AV:N) with low attack complexity and no user interaction (UI:N). The description says authentication is required, but the CVSS vector claims no privileges are needed (PR:N); the record does not resolve this contradiction, so treat both authenticated and unauthenticated reachability as possible until verified.
Exploitation
CVE-2020-15922 is not listed in CISA KEV, but public exploit references exist (Packet Storm and a third-party advisory both tagged Exploit), and EPSS is high at roughly 0.57 probability (99th percentile), indicating elevated likelihood of exploitation. No ransomware group is documented as using it.
What to do
- Apply the vendor fix for Mida eFramework or upgrade past the affected 2.9.0 release; if no patch is available, isolate or retire the product.
- Restrict network access to the eFramework interface with firewall rules or a VPN so only trusted administrators can reach it.
- Enforce strong authentication and least privilege on the application, and do not expose its management interface to the internet.
- Monitor and constrain the web server process so it cannot spawn shell commands, for example via application allowlisting or container isolation.
- Review logs and host activity for signs of compromise if the system was internet-facing before remediation.
Detection
- Alert on child processes spawned by the eFramework web server (for example sh, bash, cmd, curl, wget) using process creation telemetry.
- Inspect web and application logs for command metacharacters (;, |, &&, backticks, $()) in request parameters tied to the vulnerable endpoint.
- Monitor for outbound connections or file writes originating from the eFramework service account that are unusual for normal operation.
- Correlate authentication events with subsequent command execution to catch both authenticated abuse and any unauthenticated path.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159314/Mida-eFramework-2.8.9-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://elbae.github.io/jekyll/update/2020/07/14/vulns-01.html | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/159314/Mida-eFramework-2.8.9-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://elbae.github.io/jekyll/update/2020/07/14/vulns-01.html | ExploitThird Party Advisory |
Track CVE-2020-15922 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15922), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.